Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

🚨SEVERITY: UNKNOWNSecurity Advisory

TL;DR 📌

  • Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
  • Listed in CISA KEV (2026-09-16) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-76460.

What it is

CVE-2026-76460 affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The flaw is described as incorrect use of privileged APIs, and it sits in the web-based management interface of the affected devices.

An attacker does not need any credentials. The vulnerability allows an unauthenticated, remote attacker to bypass the web-based management interface entirely and gain unauthorised access to the device. Because ISE and ISE-PIC are typically used as policy and identity engines controlling network access, unauthorised access to the management plane here is significant regardless of the missing CVSS score.

This CVE is listed in the CISA Known Exploited Vulnerabilities (KEV) catalogue, added on 2026-09-16, so it is known to be exploited.

No CVSS score or severity rating has been published for this CVE at the time of writing, and no fixed version information is currently available.

What to do

  • Check the Cisco advisory directly (via the CVE record) for fixed releases as they become available — none are listed yet, so do not assume a patched version exists.
  • Given KEV listing, treat this as an urgent action item: identify all ISE and ISE-PIC instances in your estate and confirm whether their management interfaces are reachable from untrusted networks.
  • Restrict access to the ISE/ISE-PIC web-based management interface to trusted management networks only, using ACLs, firewall rules, or a dedicated management VLAN, until a fix is confirmed and applied.
  • Review administrative access logs on ISE/ISE-PIC for unexpected authentication or session activity, given that this flaw allows bypass of the management interface’s normal access controls.
  • Subscribe to updates on the Cisco advisory for this CVE so you are notified as soon as fixed releases are published, and apply them as a priority once available.

For leadership 🧭

Executive summary. Cisco ISE and ISE-PIC, which control network access policy, can be accessed by remote attackers without any credentials via a flaw in the management interface, and this is already being exploited in the wild. There is no fix yet, so exposure needs to be reduced today rather than waiting for a patch.

Why it matters:

  • The bypass hits the web-based management interface of ISE/ISE-PIC directly, the same interface used to administer network access policy for the whole estate.
  • No authentication is required, so any attacker who can reach the management interface over the network can gain unauthorised access to the device.
  • The CVE is in the CISA KEV catalogue as of 16 September 2026, confirming active exploitation rather than theoretical risk.
  • No fixed release exists yet, so the only current mitigation is restricting or removing network reachability to the management plane.

Now / Next / Later:

  • Now: Identify every ISE and ISE-PIC instance in the estate and check immediately whether its web-based management interface is reachable from untrusted or general-purpose networks.
  • Next: In the next change window, lock down access to the ISE/ISE-PIC management interface to a dedicated management network using ACLs or firewall rules, and review administrative access logs for unexpected authentication or session activity.
  • Later: Once Cisco publishes fixed releases for this CVE, apply them as a priority and subscribe to the advisory so future ISE/ISE-PIC management-plane issues are caught and patched without delay.

Source